fix: FP with suspicious svchost.exe rule

This commit is contained in:
Florian Roth
2021-11-26 17:12:33 +01:00
parent d91b925873
commit 9c8a649e6c
@@ -8,7 +8,7 @@ tags:
- attack.t1036 # an old one
author: Florian Roth
date: 2017/08/15
modified: 2020/08/28
modified: 2021/11/26
logsource:
category: process_creation
product: windows
@@ -22,6 +22,7 @@ detection:
- '\Mrt.exe'
- '\rpcnet.exe'
- '\svchost.exe'
- '\ngen.exe'
filter_null:
ParentImage: null
condition: selection and not filter and not filter_null